STIGQter STIGQter: STIG Summary: IBM z/OS TSS Security Technical Implementation Guide Version: 9 Release: 9 Benchmark Date: 01 Jul 2026:

IBM z/OS Time Protocol must be properly configured. IBM z/OS SNTP daemon (SNTPD) permission bits must be properly configured.

DISA Rule

SV-224024r1174004_rule

Vulnerability Number

V-224024

Group Title

SRG-OS-000355-GPOS-00143

Rule Version

TSS0-OS-000280

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Whichever Time Protocol is used, consult the system programmer for configuration information. If using SNTP with the assistance of a systems programmer with UID(0) and/or SUPERUSER access, configure the Unix permission bits and user audit bits on the SNTPD to conform to the specifications below:

/usr/sbin/sntpd 1740 faf

Check Contents

Any Time Protocol must be configured to restrict access and/or control to appropriate personnel.

Configure SNTP as shown below:

From the ISPF Command Shell, enter:
cd /usr/sbin
ls -al

If the following file permission and user audit bits are true, this is not a finding.

/usr/sbin/sntpd 1740 faf

The following represents a hierarchy for permission bits from least restrictive to most restrictive:

7 rwx (least restrictive)
6 rw-
3 -wx
2 -w-
5 r-x
4 r--
1 --x
0 --- (most restrictive)

The possible audit bits settings are as follows:
f log for failed access attempts
a log for failed and successful access
- no auditing

Vulnerability Number

V-224024

Documentable

False

Rule Version

TSS0-OS-000280

Severity Override Guidance

Any Time Protocol must be configured to restrict access and/or control to appropriate personnel.

Configure SNTP as shown below:

From the ISPF Command Shell, enter:
cd /usr/sbin
ls -al

If the following file permission and user audit bits are true, this is not a finding.

/usr/sbin/sntpd 1740 faf

The following represents a hierarchy for permission bits from least restrictive to most restrictive:

7 rwx (least restrictive)
6 rw-
3 -wx
2 -w-
5 r-x
4 r--
1 --x
0 --- (most restrictive)

The possible audit bits settings are as follows:
f log for failed access attempts
a log for failed and successful access
- no auditing

Check Content Reference

M

Target Key

4102